That is correct for those rules.
on the Lan you need this rule:
Block: any, LAN, Any, OPT1, any
this will block all traffic from your lan to the guest
currently if you plug into your guest lan, you won't get anywhere since you are blocking all connections going out.
you can ping from your lan because it is allowed on the lan, and the firewall will always allow the return traffic since an allow initiated the connection.
Just added the rule you had above and ping is still going through. And also, With block all on the Opt1 interface IT can get to everything still. its almost like the rules just don't do anything at all. The only rules i've seen work so far are ones from the wan to lan with nat.